{"id":"GHSA-9643-6xjp-vx57","summary":"Pheditor has an authenticated terminal command whitelist bypass","details":"### Summary\n\nPheditor 2.0.4 has an authenticated terminal command whitelist bypass.\n\nThe terminal feature checks whether the submitted command starts with one of the configured `TERMINAL_COMMANDS` values, then passes the full command string to `shell_exec()`. Shell command substitution such as `$()` is not blocked, so an authenticated user with the `terminal` permission can bypass a restricted command allowlist and execute arbitrary shell commands as the web server user.\n\n### Details\n\nTested repository:\n\nhttps://github.com/pheditor/pheditor\n\nTested commit:\n\n`62b43df7cb8956a9b0deb9bec278ca8676c890c5`\n\nAffected version:\n\nPheditor 2.0.4\n\nRelevant code in `pheditor.php`:\n\n- The terminal handler receives `$_POST['command']` and stores it in `$command`.\n- It blocks only `&`, `;`, and `||`.\n- It checks whether `$command` starts with one of the configured values in `TERMINAL_COMMANDS`.\n- It then passes the full command string to `shell_exec()`.\n\nRelevant logic:\n\n```php\n$command = $_POST['command'];\n\nif (strpos($command, '&') !== false || strpos($command, ';') !== false || strpos($command, '||') !== false) {\n    echo json_error(\"Illegal character(s) in command (& ; ||)\\n\");\n    exit;\n}\n\nforeach ($terminal_commands as $value) {\n    $value = trim($value);\n\n    if (strlen($command) \u003e= strlen($value) && substr($command, 0, strlen($value)) == $value) {\n        $command_found = true;\n        break;\n    }\n}\n\n$output = shell_exec((empty($dir) ? null : 'cd ' . escapeshellarg($dir) . ' && ') . $command . ' && echo \\ ; pwd');\n```\n\nBecause the whitelist check is prefix-based and the full command is executed by a shell, a command such as `ls$(...)` passes when `ls` is allowed, while the command substitution is still executed by the shell.\n\n### PoC\n\nThis was reproduced locally with Docker and PHP 8.3.\n\nFor a strict test, the configured command allowlist was changed to only allow `ls`:\n\n```php\ndefine('TERMINAL_COMMANDS', 'ls');\n```\n\nControl request:\n\n```text\ncommand=whoami\n```\n\nObserved result:\n\n```text\nCommand not allowed\nAvailable commands:\nls\n```\n\nBypass request:\n\n```text\ncommand=ls$(printf pheditor-terminal-bypass \u003e/lab/app/site/proof.txt)\n```\n\nObserved result:\n\n```text\nproof.txt is created with the content:\npheditor-terminal-bypass\n```\n\nThis shows that even when only `ls` is allowed, arbitrary shell commands can still be executed through command substitution.\n\n### Impact\n\nAn authenticated user with the `terminal` permission can bypass the intended `TERMINAL_COMMANDS` restriction and execute arbitrary shell commands as the web server user.\n\nThis affects deployments where administrators rely on `TERMINAL_COMMANDS` to restrict terminal access to a small set of safe commands.\n\nSuggested fixes:\n\n- Avoid passing user-controlled command strings to `shell_exec()`.\n- Parse the command into executable and arguments.\n- Require an exact command name match instead of prefix matching.\n- Execute without a shell, for example with an argument-array based process API.\n- If shell execution remains necessary, reject shell metacharacters comprehensively, including command substitution syntax.\n- Consider disabling the terminal feature by default.\n\nReporter credit requested:\n\nshanjijian \u003cshanjijian@gmail.com\u003e","aliases":["CVE-2026-54540"],"modified":"2026-07-28T04:14:47.222371462Z","published":"2026-07-16T20:01:05Z","related":["CVE-2026-55578"],"database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-16T20:01:05Z","nvd_published_at":null,"cwe_ids":["CWE-78"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/pheditor/pheditor/security/advisories/GHSA-9643-6xjp-vx57"},{"type":"PACKAGE","url":"https://github.com/pheditor/pheditor"},{"type":"WEB","url":"https://github.com/pheditor/pheditor/releases/tag/2.0.5"}],"affected":[{"package":{"name":"pheditor/pheditor","ecosystem":"Packagist","purl":"pkg:composer/pheditor/pheditor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.5"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.0.3","2.0.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-9643-6xjp-vx57/GHSA-9643-6xjp-vx57.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}